First published: Tue Nov 26 2019(Updated: )
It was discovered that Redmine incorrectly handle certain inputs that could cause textile formatting errors. An attacker could possibly use this issue to cause a XSS attack. (CVE-2019-17427) It was discovered that an SQL injection could allow users to access protected information via a crafted object query. (CVE-2019-18890)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/redmine | <4.0.1-2ubuntu0.1 | 4.0.1-2ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/redmine-mysql | <4.0.1-2ubuntu0.1 | 4.0.1-2ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/redmine-pgsql | <4.0.1-2ubuntu0.1 | 4.0.1-2ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/redmine-sqlite | <4.0.1-2ubuntu0.1 | 4.0.1-2ubuntu0.1 |
=19.04 | ||
All of | ||
ubuntu/redmine | <3.4.4-1ubuntu0.1 | 3.4.4-1ubuntu0.1 |
=18.04 | ||
All of | ||
ubuntu/redmine-mysql | <3.4.4-1ubuntu0.1 | 3.4.4-1ubuntu0.1 |
=18.04 | ||
All of | ||
ubuntu/redmine-pgsql | <3.4.4-1ubuntu0.1 | 3.4.4-1ubuntu0.1 |
=18.04 | ||
All of | ||
ubuntu/redmine-sqlite | <3.4.4-1ubuntu0.1 | 3.4.4-1ubuntu0.1 |
=18.04 | ||
All of | ||
ubuntu/redmine | <3.2.1-2ubuntu0.2 | 3.2.1-2ubuntu0.2 |
=16.04 | ||
All of | ||
ubuntu/redmine-mysql | <3.2.1-2ubuntu0.2 | 3.2.1-2ubuntu0.2 |
=16.04 | ||
All of | ||
ubuntu/redmine-pgsql | <3.2.1-2ubuntu0.2 | 3.2.1-2ubuntu0.2 |
=16.04 | ||
All of | ||
ubuntu/redmine-sqlite | <3.2.1-2ubuntu0.2 | 3.2.1-2ubuntu0.2 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for these Redmine vulnerabilities is USN-4200-1.
The vulnerability in Redmine allows for textile formatting errors and potential XSS attacks (CVE-2019-17427). There is also an SQL injection vulnerability that can lead to unauthorized access to sensitive information.
The affected software includes Redmine 4.0.1-2ubuntu0.1, Redmine-mysql 4.0.1-2ubuntu0.1, Redmine-pgsql 4.0.1-2ubuntu0.1, and Redmine-sqlite 4.0.1-2ubuntu0.1 on Ubuntu 19.04. It also includes Redmine 3.4.4-1ubuntu0.1, Redmine-mysql 3.4.4-1ubuntu0.1, Redmine-pgsql 3.4.4-1ubuntu0.1, and Redmine-sqlite 3.4.4-1ubuntu0.1 on Ubuntu 18.04. Additionally, it affects Redmine 3.2.1-2ubuntu0.2, Redmine-mysql 3.2.1-2ubuntu0.2, Redmine-pgsql 3.2.1-2ubuntu0.2, and Redmine-sqlite 3.2.1-2ubuntu0.2 on Ubuntu 16.04.
The severity of the Redmine vulnerabilities is not specified in the provided information.
To fix the Redmine vulnerabilities, update to the specified remedy versions: Redmine 4.0.1-2ubuntu0.1, Redmine-mysql 4.0.1-2ubuntu0.1, Redmine-pgsql 4.0.1-2ubuntu0.1, Redmine-sqlite 4.0.1-2ubuntu0.1 on Ubuntu 19.04. For Ubuntu 18.04, update to Redmine 3.4.4-1ubuntu0.1, Redmine-mysql 3.4.4-1ubuntu0.1, Redmine-pgsql 3.4.4-1ubuntu0.1, Redmine-sqlite 3.4.4-1ubuntu0.1. For Ubuntu 16.04, update to Redmine 3.2.1-2ubuntu0.2, Redmine-mysql 3.2.1-2ubuntu0.2, Redmine-pgsql 3.2.1-2ubuntu0.2, Redmine-sqlite 3.2.1-2ubuntu0.2.